This Schedule forms part of the Merchant Services Agreement between Simpli Private Limited ("Simpli") and the Restaurant. It governs the processing of personal data and prevails over the Master Terms on data-protection matters. Defined terms have the meaning given in the Master Terms; "PDPA" means the Personal Data Protection Act 2012 of Singapore. This Schedule uses the PDPA's own terms - an "organisation" (the party that determines the purposes of processing, equivalent to a "data controller") and a "data intermediary" (a party that processes personal data on another's behalf).
1. Three distinct data categories
There are three data categories under this Agreement, governed differently:
(A) Diner Data - Restaurant is the organisation, Simpli is data intermediary. For the Restaurant's own customer and order records processed by Simpli to provide the Services (order history, contact details captured at the Restaurant, order status, and similar), the Restaurant is the organisation that determines the purposes of processing and Simpli is a data intermediary processing on the Restaurant's behalf under a written contract (this Schedule), subject to the data-intermediary obligations in the PDPA (Protection, Retention Limitation, and Data Breach Notification to the organisation).
(B) Behavioural Signals - Simpli is an independent organisation. Separately and independently, Simpli collects and processes Behavioural Signals - individual-level, potentially identifiable behavioural and dining-graph signals (dining patterns, dish-preference signals, cross-venue repeat behaviour) - as a full organisation (independent controller) under the direct, unbundled consent of the Diner given through the Diner Terms (paragraph 6). For Behavioural Signals, Simpli is responsible for the complete suite of PDPA organisation obligations (Notification, Consent, Access & Correction, Protection, Retention Limitation, Transfer Limitation, and Data Breach Notification under Part 6A). Behavioural Signals are not the Restaurant's controlled Diner Data.
(C) Aggregated Behavioural Data - Simpli's owned, anonymised asset. Simpli aggregates and/or anonymises the Behavioural Signals into Aggregated Behavioural Data, from which individual Diners can no longer be identified. Once anonymised, this data is not personal data under the PDPA; Simpli owns it and may use, disclose and commercialise it as its own asset, subject to the non-diversion covenant in Master Terms clause 8.5.
How they relate. (A) is your data - Simpli only handles it to run the service for you. (B) is data a Diner separately allows Simpli to collect about the Diner's own behaviour, on consent Simpli obtains from the Diner directly (never bundled into ordering). (C) is the anonymised product Simpli builds from (B). The Restaurant's Diner Data (A) is never licensed to, or repurposed by, Simpli to build (B) or (C); those rest solely on the Diner's own consent under the Diner Terms.
2. Roles, scope and purpose (Diner Data)
2.1 Subject matter and duration. Simpli processes Diner Data for the duration of the Agreement and the wind-down/return-or-delete period in paragraph 8.
2.2 Nature and purpose. Simpli processes Diner Data solely to provide, maintain, secure and support the Services on the Restaurant's documented instructions (this Schedule and the Restaurant's use of the console being such instructions), including hosting the ordering flow, initiating charges via Stripe, surfacing order status, and providing item-popularity/ordering-trend analytics to the Restaurant.
2.3 Categories of individuals. Diners of the Restaurant.
2.4 Categories of Diner Data. Order details and items; amounts; order/payment status and Stripe transaction identifiers and card-brand name (no raw card numbers); and, where the Diner provides them, contact details and any dietary/allergen preferences the Diner selects. Simpli does not receive or store raw card data (PCI DSS SAQ-A).
2.5 Restaurant instructions and lawful basis. Simpli will process Diner Data only on the Restaurant's documented instructions and as needed to provide the Services or comply with law. The Restaurant warrants it has a lawful basis (including any consent and notification required of it as organisation) for the collection and use of Diner Data through the Services. Simpli will inform the Restaurant if, in Simpli's opinion, an instruction infringes the PDPA.
2.6 Restaurant remains accountable. Appointing Simpli as a data intermediary does not relieve the Restaurant of its own PDPA obligations to its Diners; the Restaurant is deemed to have the same obligations in respect of Diner Data processed on its behalf.
3. Simpli's intermediary obligations (Diner Data)
As data intermediary for Diner Data, Simpli will:
3.1 Protection. Implement reasonable and appropriate technical and organisational security measures to protect Diner Data against unauthorised access, collection, use, disclosure, copying, modification, disposal or loss, appropriate to the risk. Simpli's compliance baseline is the PDPA. Simpli makes no SOC 2, ISO 27001, HIPAA or BAA claim.
3.2 Retention limitation. Not retain Diner Data longer than necessary for the Services or as required by law, and cease retention as set out in paragraph 8. Simpli's default retention target for identifiable Diner Data after account closure is up to 90 days (subject to statutory retention in paragraph 8.2), unless the Restaurant instructs earlier deletion.
3.3 Confidentiality and access control. Ensure personnel authorised to process Diner Data are bound by confidentiality and access it on a need-to-know basis.
3.4 Assistance. Provide reasonable assistance to the Restaurant, taking into account the nature of processing, to respond to Diner access/correction requests and to meet the Restaurant's own PDPA obligations.
3.5 Data breach notification to the Restaurant. For a data breach affecting Diner Data, Simpli will notify the Restaurant without undue delay after becoming aware of it, with available details to help the Restaurant assess and, where required, notify the PDPC and affected individuals. For Diner Data, the Restaurant as organisation is the party responsible for any regulatory and individual notification, with Simpli's support; the timing of any PDPC notification for Diner Data is the Restaurant's decision. (Simpli's own PDPC-notification duty for the data it controls - the Behavioural Signals - is dealt with separately in paragraph 6.5, and is not a contractual service level for Diner Data.)
4. Sub-processors
4.1 The Restaurant authorises Simpli to appoint sub-processors to provide the Services, provided Simpli imposes on each sub-processor data-protection obligations no less protective than this Schedule and remains responsible for their performance in respect of Diner Data.
4.2 Current principal sub-processors include:
| Sub-processor | Function | Processing location |
|---|---|---|
| Stripe | Payment processing (diner charges, Connect) | Outside Singapore (comparable-protection terms) |
| Resend | Transactional email | Outside Singapore |
| Google (OAuth) | Diner sign-in | Outside Singapore |
| Zoho | Business email / support | Outside Singapore |
| Sentry | Error monitoring | Outside Singapore |
| BetterStack | Logging / uptime monitoring | Outside Singapore |
| Fly.io | Application hosting / compute | Primarily Singapore (sin region) |
4.3 Simpli maintains a sub-processor register and will give the Restaurant reasonable prior notice of any intended addition or replacement of a sub-processor that processes Diner Data. If the Restaurant reasonably objects on data-protection grounds, the Parties will discuss in good faith; failing resolution, the Restaurant may terminate under clause 15.2 of the Master Terms.
5. Overseas transfer
5.1 Data and compute run primarily in Singapore (Fly.io sin region). Certain sub-processors (including those in paragraph 4.2) process personal data outside Singapore.
5.2 Where Diner Data is transferred outside Singapore, Simpli will ensure the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the PDPA (e.g. through contractual terms, the recipient's own certifications, or applicable data-transfer mechanisms), in accordance with the Transfer Limitation Obligation.
6. Behavioural Signals and Aggregated Behavioural Data: lawful basis, ownership and Simpli's own obligations
6.1 Diner-facing consent (unbundled). Simpli collects and processes Behavioural Signals under consent obtained from the Diner directly through the Diner Terms at the Simpli-facing checkout. That consent is separate from, and not a condition of, the Diner's ability to order and pay: a Diner may decline it and still order and pay. This Agreement does not purport to give, and Simpli does not rely on, the Restaurant's consent on any Diner's behalf for this purpose.
6.2 Consent-compliance warranty. Simpli warrants that the Diner Terms and consent flow are designed to meet PDPA ss. 13–14 (consent, including the s. 14(2)(a) prohibition on requiring consent beyond what is reasonable to provide the product or service - i.e. no forced or bundled consent), s. 18 (limits of purpose) and s. 20 (notification of purpose).
6.3 Independent organisation; sequencing. Simpli processes identifiable Behavioural Signals strictly on the basis of that direct diner consent, as an independent organisation (controller), and meets the full PDPA organisation obligations for them (Notification, Consent, Access & Correction under ss. 21–22, Protection, Retention Limitation, Transfer Limitation, and Data Breach Notification). Simpli then aggregates and/or anonymises those Behavioural Signals; only the resulting Aggregated Behavioural Data (from which individuals can no longer be identified, and which is therefore not personal data) is the proprietary asset that Simpli owns and may commercialise.
6.4 No Restaurant rights; no restriction on Simpli (except the covenant). The Restaurant's rights in respect of Diner Data (paragraphs 1–5) do not extend to the Behavioural Signals or the Aggregated Behavioural Data and do not restrict Simpli's ownership or use of them, save for the non-diversion covenant and own-venue licence-back in Master Terms clauses 8.5–8.6. The Restaurant's controlled Diner Data is never licensed to, or repurposed by, Simpli to create the Behavioural Signals or the Aggregated Behavioural Data.
6.5 Simpli's own breach notification. For a breach of the Behavioural Signals (personal data Simpli controls in its own right), Simpli - as the responsible organisation - will assess the breach and, where it is a notifiable breach, notify the PDPC as soon as practicable and in any case no later than 3 calendar days after determining it is notifiable, and notify affected individuals as required by PDPA Part 6A. This is independent of the Diner-Data intermediary flow in paragraph 3.5.
6.6 Diner access and correction. Simpli provides Diners with a means to exercise access and correction rights (PDPA ss. 21–22) in respect of the identifiable Behavioural Signals Simpli holds about them, and to withdraw consent, as described in the Diner Terms.
6.7 Sensitive data. Any diner health/dietary preference data is treated as sensitive personal data, is separately consent-gated at the diner level, and is not used to provide medical advice. Simpli makes no HIPAA/BAA claim and there is no US-healthcare use case.
7. Restaurant obligations
7.1 The Restaurant will: (a) act as the organisation for Diner Data in compliance with the PDPA, including providing any required notifications and obtaining any required consents for its own collection and use; (b) only submit Diner Data it is entitled to process; (c) keep Diner Data in the console accurate; and (d) appoint and publish its own Data Protection Officer as required by the PDPA (s. 11(3)).
8. Return and deletion on termination
8.1 On termination or expiry of the Agreement, and after making available the Restaurant's data export under clause 15.5(d) of the Master Terms, Simpli will cease processing Diner Data (other than for wind-down of in-flight orders) and will, at the Restaurant's election, return and/or delete the Diner Data within a reasonable period and in any case within 30 days of the Restaurant's instruction.
8.2 Statutory retention. Simpli may retain records to the extent required by law (including financial/transaction records, typically for up to 5 years under Singapore tax/records law). Where such records are retained, the identifiable link to the Diner is severed / anonymised so the retained records are not kept in identifiable form beyond what the law requires.
8.3 Simpli's ownership and retention of the Behavioural Signals and Aggregated Behavioural Data (paragraph 6) is unaffected by termination and survives, subject to Simpli's continuing PDPA obligations for any Behavioural Signals still held in identifiable form and to the Master Terms clause 8.5 covenant.
9. DPO and contact
9.1 Simpli has designated a Data Protection Officer whose business contact is privacy@simpli.sg (PDPA s. 11(3)/(5)). [Insert DPO name/role before use.] Commercial notices may be sent to shaun@simpli.sg.
9.2 This Schedule survives termination for as long as Simpli processes or retains any Diner Data, and paragraphs 6 and 8.3 survive for as long as Simpli holds the relevant data.